Jump to content

Recommended Posts

Posted
I can think of two or possibly three instances where we require parents to give personal details directly to an external company. Are we outside of this altogether since the parents give the data themselves or are we joint Controllers with the other company since we established the relationship? What responsibilities do we have (DPIAs etc) since we don't give the parents much choice about sharing this data?
Posted (edited)

I'm not 100% sure about this one!

 

 

The example I can think of is if your say to parents, to pay for schools dinners you must register with a third party payment service. Is this the kind of thing that you mean?

 

 

The test to be a controller is if you determine the purposes for processing the data and the means of processing it then you are the controller. I see this as meaning the "why" you are processing it and the "how" you are processing it.

 

So in my example of school dinner payments, the school is determining why the data needs to be processed. You are telling the parent, you must give this third party company your details so we can process school dinner payments.

 

But... the third party is determining how they process the data.

 

 

I'l use my example and apply it to some questions that you must ask yourself to help determine if you are the controller...

 

 

Why are you collecting the personal data in the first place? (school decides it is being collected it to process school dinners)

 

Which items of personal data is collected? (third party decides what they need, i.e name, address, debit card details etc but there is a little influence by the school. The school is saying you must register with the third party to pay for school dinners so clearly they are telling the parent they will need to provide some online payment method)

 

The purpose for collecting the data? (joint responsible, school is giving the overall purpose but the third party decides the purpose for the individual data sets, i.e why do we need the debit card, why do we need the name etc)

 

Which individual to collect data about (school decides, i.e. all students need to use it, or just year 1&2 students or all students apart from students on free school meals)

 

How long to retain the data (both, the school tells them how long the student is there for, but the company will be responsible for deleting the data)

 

Whether to disclose the data, and if so, to who, (the third party with a little bit of the school, for example the school may ask how much credit the person has on their payment account)

 

The above questions can only be answered by the data controller so if you answer yes to them, I'd say you have controller responsibility.

 

 

The data processer decides thing like what IT systems to use, how to store the data, the security of the data, the retention methods, backup strategies etc.

 

If you are required by law to process the personal data, (I'm thinking legal obligations like recording child protection incidents or registers) then the school must retain their data controller responsibilities.

 

 

From my example I think the decision will be either the school is a data controller and the third party is the processer OR joint controller. I'd be willing to edge towards both having controller responsibilities so I'd be asking the third party to provide details on what data they collect about our parents, how they collect it, how they store it, is it encrypted, is it within the EU, how long do they keep the data etc. This should all be document to protect the school in case of a breach by the third party.

 

I can't think of an example where you are telling people they have to provide a company personal data, but then you have absolutely no controller responsibility.

 

Hope this helps!

Edited by rom1984
Posted

Thanks for your thoughts @rom1984 I had intended not to mention the companies/processes involved as I didn't want the thread to get sidetracked with talk about specific solutions or overlook similar scenarios other schools might have, but it might be better if I give more detail so you can all understand exactly what my quandary is. The scenarios I'm talking about are:

 

1 - uniform supplier - uniform can only be bought from one place; we provide order forms then collect completed forms and cheques which we pass on to the uniform supplier. Parents can also email completed forms to the supplier and pay direct into his bank if they wish. We do not pass any information to the supplier ourselves, other than what the parents wrote on the forms; we keep no record of the transaction. So, I'm pretty sure we're not the Controller here, as all we do is facilitate the engagement, BUT... if the uniform supplier had a breach or voluntarily shared data, would there be liability on us, since we had told the parents they had to give that information over? Should we therefore ensure he agrees not to share the data (almost certainly) but should we also ensure he is encrypting it on his PC?

 

1b - if we were to start taking orders and payment for uniform through our online payment portal, then passing the details and money on to the supplier, would this change anything about the relationship or responsibilities?

 

2- cashless payment provider, where we pass some details to the payment provider (name, email address, etc.) and the parents themselves then give credit card information directly to the supplier, who then processes it. We are clearly Controllers here so have done our own DPIA, but, as above, if there were to be a breach and the payment provider disclosed parents' credit card details, would we have some liability in that, since even though we neither processed nor disclosed the credit card details, we had required the parents to give them to the company who did disclose them?

 

3 - (less concerned about this one as it is voluntary) expedition organiser through Duke of Edinburgh who ask parents to provide contact information and medical details. We don't pass any information to the organiser ourselves, and their consent form makes it clear how they process the data, so my view is we're not the Controller there, but do we have a responsibility (moral if not legal) to ensure the organiser is acting responsibly and legally, and again if there were a breach, what is our level of liability?

 

Hopefully that clears up exactly what I'm asking...

Posted (edited)

1 - this is a tricky one I'm not 100% sure off, might be a call to the ICO helpline. This is my own thoughts on it thinking out loud...

 

The school is determining why they are processing the order (to provide a school uniform), they are also determining how they are processing it - i.e they provide an order form, collect the form, they manage the handing over of the cheques, they provide details on how to go directly to the supplier. That straight away says to me the school is the controller and the supplier is the processors.

 

You would have to think about the lawful bases that you are processing this data too. You couldn't collect this data on the bases of consent because the parents has no choice. They either hand over their personal details or their child can not go into school. So I think it would be the school that would need to determine on what bases they are processing the data which further suggests they are the controller.

 

At the very very very least the school would need to find out how the shop is protecting personal data because the school is forcing parents to give the shop their details. If the shop comes back and says they process data on their laptop and its not encrypted, this should scream alarm bells and the school needs to decide are they happy forcing parents to give personal details to a company that doesn't have basic protection procedures in place. If they decide they are happy with doing this, they would unquestionably hold some responsibilities, and I image quite a high level of it.

 

1b - I don't think it would because of above. Because you are thinking about other methods to collect the data I think this further suggests you are the controller too, the school is determining how the data is collected whether it be order form, online, direct with the supplier.

 

 

2 - I think in this example the ICO would look at Article 5 of the GDPR and ask did the school act fairly and reasonably in the matter. So for example they would ask you to show documentation on how you assessed the risks of using the specific company.

You could then provide them a contract or an agreement that said the third party agreed that all the credit card details they kept were encrypted, the credit card details were pseudonymised etc etc. If the breach was then just human error by someone from the third party, then the school can show that the issue was with the third party controller. If the third party comes back and says we don't encrypted our credit card details, and the school still chooses to use that supplier, then the school would share some responsibility.

 

3 - I think this is similar to the above. Because you are basically giving the parent no option but to hand over their details to a company, you must have at least an obligation to check that the company is handling the data properly.

 

I think the main take away point is that the school needs to act fairly and needs to be able to show it acted fairly. If you give the parent no option but to hand over their details to a third party in order to access a part of the schools curriculum, then it is fair of the parents to presume that the school has checked that the third party handles personal data properly (see Article 5 of the GDPR for what I mean by handled properly)

Edited by rom1984
Posted
The school is determining why they are processing the order (to provide a school uniform), they are also determining how they are processing it - i.e they provide an order form, collect the form, they manage the handing over of the cheques, they provide details on how to go directly to the supplier. That straight away says to me the school is the controller and the supplier is the processors.

 

You see, I'm not sure that's entirely true. I don't think the school determined how those things would be done, I suspect the supplier said what they'd like and we agreed (or is that the same as us determining it?).

 

At the very very very least the school would need to find out how the shop is protecting personal data because the school is forcing parents to give the shop their details. If the shop comes back and says they process data on their laptop and its not encrypted, this should scream alarm bells and the school needs to decide are they happy forcing parents to give personal details to a company that doesn't have basic protection procedures in place. If they decide they are happy with doing this, they would unquestionably hold some responsibilities, and I image quite a high level of it.

 

And that is the reason for some of my concern here - I wouldn't be surprised to find the data is not encrypted on the supplier's laptop and the forms are not being handled as one should handle confidential paperwork. It is certainly a question we need to ask them.

 

2 - I think in this example the ICO would look at Article 5 of the GDPR and ask did the school act fairly and reasonably in the matter. So for example they would ask you to show documentation on how you assessed the risks of using the specific company.

You could then provide them a contract or an agreement that said the third party agreed that all the credit card details they kept were encrypted, the credit card details were pseudonymised etc etc. If the breach was then just human error by someone from the third party, then the school can show that the issue was with the third party controller. If the third party comes back and says we don't encrypted our credit card details, and the school still chooses to use that supplier, then the school would share some responsibility.

 

So the DPIA we would be doing anyway covers this eventuality, as we're certainly not going to give the contract to a company that doesn't encrypt/protect this sort of information.

 

3 - I think this is similar to the above. Because you are basically giving the parent no option but to hand over their details to a company, you must have at least an obligation to check that the company is handling the data properly.

 

In this instance you could argue as it is a voluntary extra-curricular activity, we are giving them a choice (they choice being not to participate) but I take your point we have some responsibility to check they're handling it appropriately.

 

I think the main take away point is that the school needs to act fairly and needs to be able to show it acted fairly. If you give the parent no option but to hand over their details to a third party in order to access a part of the schools curriculum, then it is fair of the parents to presume that the school has checked that the third party handles personal data properly (see Article 5 of the GDPR for what I mean by handled properly)

 

Sounds like there are two more companies to add to the list for DPIAs then.

Posted
You see, I'm not sure that's entirely true. I don't think the school determined how those things would be done, I suspect the supplier said what they'd like and we agreed (or is that the same as us determining it?).

 

 

.

 

Yep that's a fair point, on seconds thoughts I think your right the supplier will determine how they collect the data (i.e they give the school the order form and tell them how they want it). But I think the school defiantly sets out why they need to process the order, they are mandating that parents have to go to that specific shop and order the specific uniform. I think it would be different if you said you can buy any grey jumper and black pants then you wouldn't be involved. But as you have said, because you are saying the parent must go to that shop than you are determining why the person is in the shop processing the order.

 

Sounds like your on it with the rest of the other bits!

Posted
I can think of two or possibly three instances where we require parents to give personal details directly to an external company. Are we outside of this altogether since the parents give the data themselves or are we joint Controllers with the other company since we established the relationship? What responsibilities do we have (DPIAs etc) since we don't give the parents much choice about sharing this data?

 

The school can only 'require' what is legislated for, and beyond that the borders of what systems a parent/child can ask not to be part of, are less clear. Where for example however a school has passed information out of the SIMs (for which the school is the controller), the school would remain the controller or joint controller (i.e cashless systems).

 

This is one topic we believe there needs to be UK-wide clarity on from the ICO, because what is the boundary of "required" as it's not at all clear in practice and affects who is accountable for it. (much of our current work). PS if you've not already done so, pls consider doing the survey and add this question into the end "what have we not asked" question in the survey and we'll include it in upcoming report FAQs. (Average completion time so far, 9 minutes >> Please complete the survey here before 12:00 midday on February 14th >> https://www.surveymonkey.co.uk/r/GDPR_support ) Thanks.

Posted

One of the things we have to remember here is that the data processor is forging a direct relationship with the parent at times ... so the relationship is one of data subject and data controller.

So it is quite feasible for youto have joint data controllers with data elements relating to you, the parent and the processor ... and then additionally they may be a data controller on their own, or have joint data controller activities with other schools (think about services that give parents access to things across multiple schools).

 

So, simple answer, yes, you may have suppliers that are joint data controllers, but you should also put things in place it people do not want to use those services.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...